PT-2019-11838 · Hewlett Packard+1 · Hp Alm+2

·

CVE-2019-10444

·

Publicado

2019-10-16

·

Atualizado

2023-10-25

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Bumblebee HP ALM Plugin versions 4.1.3 and earlier
Description The issue concerns the Jenkins Bumblebee HP ALM Plugin unconditionally disabling SSL/TLS and hostname verification for connections to HP ALM. This means that the plugin did not validate the identity of the HP ALM server it was connecting to, which could allow for man-in-the-middle attacks. The plugin now allows users to opt out of certificate validation, addressing the previous unconditional disabling of SSL/TLS certificate validation.
Recommendations For Jenkins Bumblebee HP ALM Plugin versions 4.1.3 and earlier, update to a version that allows users to opt out of certificate validation to mitigate the risk of exploitation. As a temporary workaround, consider restricting access to the HP ALM service to minimize the risk of unauthorized connections.

Correção

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-10444
GHSA-QGP8-H5CP-R75R

Produtos afetados

Hp Alm
Jenkins
Jenkins Bumblebee Hp Alm Plugin